Method for the Detection of Internal Threats in Academic Campus Networks
摘要
The current academic campus intranets demand higher requirements to satisfy the needs of their users. The greatest threat lies in the people with access to and knowledge of the organization. This research adapts the OSSTMM V 3.0 methodology to estimate the security breaches caused by the human channel (users) within the intranet, measuring porosity, limitations, and processes, evaluating the security risk (Rav) in 85.77%, and determining 13.92% of vulnerabilities and anomalies that an internal user can exploit. The analysis of the intranet with NIDS-SNORT (Network Intrusion Detection System) to determine internal threats in real-time corroborates the analysis of the human channel. The identified threats allow an exploitation study of SMB EternalBlue to be carried out, which enables the evaluation of the affectation of the threats to the users in a test scenario, in addition to the solution to these vulnerabilities. This novel method using free software responds to Ecuadorian universities’ need to have a standard that, based on vulnerability analysis, allows the implementation of security policies at the institutional level.